[SIGNALS WEEKLY] Shifting Access Paths: OT, Identity, and Adversarial AI
Some of this week’s most useful threat signals point to access paths that sit just outside the normal inventory: a cellular modem added by an OT integrator, a hotel captive portal steering a traveler toward token theft, or a passkey implementation that trusts the wrong lifecycle step.
TL;DR
- [Critical Infrastructure/OT] Internet-exposed PLCs—often via undocumented cellular modems and integrator remote access—are driving real-world water-utility lockouts, manual operations, and safety impacts, highlighting systemic OT discovery and access-control gaps.
- [Espionage/Identity] State actors and criminals are converging on identity seams—captive-portal traffic manipulation, OAuth/device-code abuse, and emerging passkey implementation flaws—to achieve durable, passwordless account takeover against high-value travelers and admins.
- [Threat Tradecraft/AI] Adversaries now use AI as an operational “co-pilot” (tooling development, phishing workflow automation, evasion of safety controls), signaling that detection must pivot from prompt content alone to surrounding infrastructure, behavior, and abuse patterns.
AlphaHunt
Stop doomscrolling, start decisioning. We chewed through the muck so your team doesn’t have to. → Subscribe!
Like this? Forward this to a friend!
(Have feedback? Did something resonate with you? Did something annoy you? Just hit reply! :))
Current Stories
TL;DR
- [Critical Infrastructure/OT] CISA warned of a significant increase in threats targeting internet-exposed PLCs in the U.S. water sector; observed impacts include lockouts (password changes), PLC disconnects (IP changes), boil-water notices, and sustained manual operations.
- Key exposure driver: undocumented cellular modems and remote access paths installed by vendors/integrators.
- [Espionage/Identity] Microsoft attributed “CaptiveCrunch” to Storm-2945 (assessed sub-cluster of Midnight Blizzard/SVR): hospitality captive portals used for DNS/HTTP manipulation to steer travelers into credential/token theft.
- Concrete detail: lures include device-code/OAuth phishing and “fake update / ClickFix” prompts; malware described includes Go-based Windows RATs and in-memory PowerShell infostealers targeting M365 tokens, browser cookies, and Wi‑Fi credentials.
- [Vulnerabilities/KEV] CISA added CVE-2026-18577 (N-able N-central authentication bypass via alternate path/channel) to the KEV Catalog, reinforcing active exploitation risk and prioritization for patching/mitigation on exposed assets.
- [Supply Chain/Policy] CISA + NSA + FBI + partners published updated “2026 Minimum Elements for an SBOM,” replacing the 2021 NTIA baseline and explicitly calling out modern software types (including AI and SaaS) where additional elements may be required.
- [AI/Threat Enablement] Cisco Talos reported increasing adversary use of AI based on recovered prompt-log artifacts, showing AI is being used as a practical “ops assistant,” not just novelty.
- Concrete detail: examples include AI-assisted development of DDoS tooling tied to a claimed bot pool of ~2,000 Android TVs and building bulk-mail validation workflows using innocuous “privacy policy update” tracking emails; bypass patterns include “ownership/CTF/bug bounty” pretexts and task decomposition.
References
- (2026-07-30) CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
- (2026-07-31) CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- (2026-08-03) CISA Adds One Known Exploited Vulnerability to Catalog
- (2026-07-29) 2026 Minimum Elements for a Software Bill of Materials (SBOM)
- (2026-08-04) Keep going, bro. You’ve got this! A data-driven look at how adversaries are weaponizing AI
Emerging Stories
TL;DR
- [Identity/Authentication] Unit 42 described “Pass-ta-key” attack classes where endpoint malware plus relying-party validation gaps (e.g., weak user-verification enforcement) can enable passkey-protected account takeover in synced passkey ecosystems.
- [Supply Chain/macOS] Unit 42 reported XCSSET v40’s resurgence: seeding via Xcode projects (incl. open-source), more memory-resident behavior, local worming across Xcode projects, defense impairment, and expanded browser-hijack/trojanizer modules.
References
- (2026-08-03) Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
- (2026-07-31) The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version